1---2name: compare-data-processing-agreement-against-internal-privacy-s3description: Vendor DPA deviation reports are strongest when the agent benchmarks the agreement against the relevant internal privacy standards and any applicable external requirements, then converts each gap into a structured deviation analysis with practical negotiation guidance.4---56# Skill: Compare Vendor Data Processing Agreement Against Internal Privacy Standards — Deviation Report78## 1. Subject-matter triage9- Identify the governing benchmark set before comparing text: the internal privacy playbook, the HIPAA checklist, and any supporting privacy or security documents included in the review packet.10- Distinguish mandatory legal or regulatory requirements from internal policy preferences, and treat the stricter applicable standard as controlling where benchmarks overlap.11- Confirm the deliverable is an issue/deviation report, not a redline; preserve comparison and negotiation guidance rather than drafting substitute contract language unless a proposed alternative is requested.12- If the packet includes a transmittal email or similar context, use it to gauge deal sensitivity, timing pressure, and realistic negotiation posture.1314## 2. Failure modes the skill is correcting15- Benchmarking the DPA against only one standard and missing separate obligations in the other review materials.16- Treating all gaps as equal and failing to classify whether a deviation is legally required, policy-driven, or a negotiable preference.17- Reviewing sub-processor provisions in the abstract without checking the actual disclosed sub-processor list and any stated locations or transfer paths.18- Ignoring email or deal context that affects which deviations should be escalated, narrowed, or accepted.19- Stating that a clause is noncompliant without tying the conclusion to the controlling legal or policy authority.20- Listing issues without giving a practical next step or negotiating position for each one.2122## 3. Legal frameworks / domain conventions that apply23- Apply the governing privacy and data-processing rules implicated by the DPA, including the basic controller/processor or service-provider allocation reflected in the source documents.24- Apply HIPAA-oriented checklist requirements where the processing involves protected health information or a healthcare context; verify the agreement contains the required contractual protections and flow-down obligations.25- Apply the internal privacy playbook as an independent benchmark, recognizing that internal standards may exceed baseline legal requirements.26- Apply standard vendor DPA conventions for confidentiality, security controls, breach notice timing, audit rights, subprocessors, deletion/return, assistance obligations, international transfers, and liability allocation.27- Where the source set identifies a specific authority, follow that authority as framed in the documents; where it does not, cite the generally recognized rule or practice supporting the conclusion.2829## 4. Analytical scaffolds30- Read all benchmark documents in parallel and create a single comparison map of required, preferred, and prohibited positions.31- Review the DPA clause by clause and, for each provision, record:32 - what the vendor paper says,33 - what the internal privacy playbook requires,34 - what the HIPAA checklist requires,35 - what any supporting document adds,36 - and the resulting deviation.37- For each deviation, assess:38 - whether the gap is absolute or conditional,39 - whether it is cured elsewhere in the packet,40 - whether the issue is driven by the text, the sub-processor list, or the transmittal context,41 - and what business or regulatory consequence follows if it is left unresolved.42- Classify each deviation on a uniform ordinal severity scale defined once at the top of the report, and use that scale consistently across all entries.43- Close each issue with three elements: the scale or magnitude of the gap using figures or thresholds supplied in the source materials when available; the cross-reference to the related clause, schedule, list, or document; and the practical consequence for the client.44- When multiple vendors, entities, data flows, or processing locations are in scope, enumerate them first and analyze each separately rather than collapsing them into one pass.4546## 5. Vertical / structural / temporal relationships47- Read the DPA together with the sub-processor list, not in isolation; a generic authorization clause may be insufficient once the specific listed processors and locations are considered.48- Read security, audit, breach, deletion, and assistance clauses as an integrated control set; weakness in one often changes the risk rating of the others.49- Use the transmittal email and negotiation history, if provided, to distinguish hard stops from points that can be deferred, narrowed, or accepted.50- Where internal standards and external requirements diverge, explain both and apply the more protective requirement unless the source documents expressly permit a lesser standard.51- Consider timing relationships: notice periods, cure windows, renewal or go-live timing, and response deadlines can change the severity of an otherwise ordinary deviation.5253## 6. Output structure conventions54- Produce a deviation report with an executive summary followed by a table of issues.55- Define the severity scale once near the top, using ordinal labels such as Critical, High, Medium, and Low, and apply it uniformly.56- For each row, include a clear clause reference, the vendor position, the benchmark requirement, the classification, the severity, and a negotiation position or fallback drafting suggestion.57- Include a brief assessment of overall vendor posture and a short set of recommended actions that assigns responsibility and urgency.58- Surface verbatim quotes from internal documents only when necessary for precision; do not copy unnecessary text from the source packet.59- Keep the deliverable file name exactly as instructed: `dpa-deviation-report.docx`.